<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: failover key in PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281592#M758473</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sakishor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cureently the firewall are running on the lan based cable failover, there is no failover key set for the same. now i have set the same without any downtime...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Oct 2009 03:37:43 GMT</pubDate>
    <dc:creator>CSCO10905906</dc:creator>
    <dc:date>2009-10-07T03:37:43Z</dc:date>
    <item>
      <title>failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281582#M758211</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Recently a audit point was raised by auditor, that the failover key is not enabled for the failover(PIX 515).&lt;/P&gt;&lt;P&gt;Please let  me know how to enable the failover key between the PIX firewall without any downtime.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281582#M758211</guid>
      <dc:creator>CSCO10905906</dc:creator>
      <dc:date>2019-03-11T16:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281583#M758219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Failover is a licensed feature - you probably have a restricted license. If you want to have fail over functionality - you need to purchase it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However is sounds like you are not using fail over anyway - and the auditor is just pointing it out.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need it - you need to buy it and another PIX device to failover to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 07:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281583#M758219</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-06T07:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281584#M758241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hi andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pix firewalls are already running on active-standby mode, but there is no failover key configured on the same.now the point is to set the failover key on the firewalls without any downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 08:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281584#M758241</guid>
      <dc:creator>CSCO10905906</dc:creator>
      <dc:date>2009-10-06T08:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281585#M758274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh sorry - are you saying that you are missing the failover shared secret key ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the 2 devices in config sync?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 08:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281585#M758274</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-06T08:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281586#M758304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewalls are in sync and working fine in active-standby mode. the objective is to set the failover key for closure of the audit point without any downtime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 08:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281586#M758304</guid>
      <dc:creator>CSCO10905906</dc:creator>
      <dc:date>2009-10-06T08:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281587#M758339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well - if you configure the primary active firewall with the failover key, it will be replicated to the secondary and should not cause any interuption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to be sure - perhaps configure it out of hours, just to be sure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 09:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281587#M758339</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-06T09:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281588#M758369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Export Certificate/Private Key in Failover Configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The primary device automatically replicates the private key/certificate to the secondary unit. Issue the command write memory in the active unit in order to replicate the configuration (which includes the certificate/private key) to the standby unit. All the keys/certificates on the standby unit are erased and repopulated by the active unit configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: You must not manually import the certificates, keys, and trust points from the active device and then export to the standby device.&lt;/P&gt;&lt;P&gt;WARNING: Failover message decryption failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Failover message decryption failure. Please make sure both units have the &lt;/P&gt;&lt;P&gt;    same failover shared key and crypto license or system is not out of memory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This problem occurs due to failover key configuration. In order to resolve this issue, remove the failover key, and configure the new shared key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 09:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281588#M758369</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-06T09:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281589#M758393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well from what i have seen, unlike an ASA which uses just 1 licence for both pri and failover device, a pix uses 2 types of licence, a unrestricted and a failover one. &lt;/P&gt;&lt;P&gt; if the you enter the standby activation key in the primary device, why would the primary reflect this on the standby device, the activation key is one part which is not replicated, and the reason for this being that activation is NOT a part of the configs set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please clarify as i am still new into the world of networks and this is just something i have observed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 10:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281589#M758393</guid>
      <dc:creator>uzair syed naveed</dc:creator>
      <dc:date>2009-10-06T10:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281590#M758414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This post is actually refering to failover config - not licensing, my fault as that is what I first thought this was about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with some of what you say, however you can have a device with a restricted license - BUT contains failover functinonality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not be able to put an unrestrcited feature activation key into an restricted device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a specific issue that I or the Netpro forum can help with?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 11:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281590#M758414</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-06T11:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281591#M758441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using a cable based failover you dont really need to configure a failover key on the security appliance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover key is only to encrypt all the communication between the failover devices. If failover key is not specified the communication between the failover devices happen in a clear text. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the PIX security appliance platform, if you are using the dedicated serial failover cable to connect the units, then communication over the failover link is not encrypted even if a failover key is configured. The failover key only encrypts LAN-based failover communication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information you can refer to the following link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/ef.html#wp1927595" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/ef.html#wp1927595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do let me know if you have any further questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Oct 2009 23:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281591#M758441</guid>
      <dc:creator>Saurabh Kishore</dc:creator>
      <dc:date>2009-10-06T23:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: failover key in PIX</title>
      <link>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281592#M758473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sakishor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cureently the firewall are running on the lan based cable failover, there is no failover key set for the same. now i have set the same without any downtime...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Oct 2009 03:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-key-in-pix/m-p/1281592#M758473</guid>
      <dc:creator>CSCO10905906</dc:creator>
      <dc:date>2009-10-07T03:37:43Z</dc:date>
    </item>
  </channel>
</rss>

